CGRC Exam Question 51
Process of formally evaluating the degree of threat to an information system or enterprise and describing the nature of the threat.
Response:
Response:
CGRC Exam Question 52
Which of the following describes residual risk as the risk remaining after risk mitigation has occurred? Response:
CGRC Exam Question 53
A written plan for recovering one or more information systems at an alternate facility in response to a major hardware or software failure or destruction of facilities.
Response:
Response:
CGRC Exam Question 54
FIPS 199, Standards for Security Categorization of Federal Systems defines which 3 Security Categories? Response:
CGRC Exam Question 55
What is included in a POA&M that is presented to the Approving Authority as part of the initial authorization package?
Response:
Response:
